{"id":238,"date":"2009-12-07T18:42:10","date_gmt":"2009-12-08T01:42:10","guid":{"rendered":"http:\/\/www.mattjm.com\/wordpress\/?p=238"},"modified":"2019-05-28T09:07:41","modified_gmt":"2019-05-28T17:07:41","slug":"client-certs-and-windows-server-2008","status":"publish","type":"post","link":"https:\/\/www.mattjm.com\/blog\/2009\/12\/07\/client-certs-and-windows-server-2008\/","title":{"rendered":"Client Certs and Windows Server 2008"},"content":{"rendered":"<p>I just spent a while tracking down a cert problem while migrating an app to IIS7 on Windows Server 2008.<\/p>\n<p>This app taps into a web service using a client cert. I finally tracked the problem down to a permissions issue with the private key on the client certificate. On Server 2003 and earlier these permissions are managed with the winhttpcertcfg.exe tool, but that&#8217;s not available on Server 2008 (or at least not supported, as far as I can tell). Turns out it&#8217;s actually pretty simple, though. See screenshot below:<\/p>\n<p><a href=\"http:\/\/mattjm.com\/blog\/wp-content\/uploads\/2009\/12\/cert.jpg\"><img loading=\"lazy\" class=\"alignnone size-full wp-image-240\" title=\"Windows Server 2008 Client Cert\" src=\"http:\/\/mattjm.com\/blog\/wp-content\/uploads\/2009\/12\/cert.jpg\" alt=\"Windows Server 2008 Client Cert\" width=\"557\" height=\"231\" srcset=\"https:\/\/www.mattjm.com\/blog\/wp-content\/uploads\/2009\/12\/cert.jpg 557w, https:\/\/www.mattjm.com\/blog\/wp-content\/uploads\/2009\/12\/cert-300x124.jpg 300w\" sizes=\"(max-width: 557px) 100vw, 557px\" \/><\/a><\/p>\n<p>Yeah&#8230;just a simple right-click on the cert in the certificates snap-in. Also, for getting SSL traces, this blog had a good system.diagnostics section:<\/p>\n<p><a href=\"http:\/\/blogs.msdn.com\/asiatech\/archive\/2009\/04\/08\/using-system-net-trace-to-troubleshooting-ssl-problem-in-net-2-0-application.aspx\">http:\/\/blogs.msdn.com\/asiatech\/archive\/2009\/04\/08\/using-system-net-trace-to-troubleshooting-ssl-problem-in-net-2-0-application.aspx<\/a><\/p>\n<p>The microsoft documentation, as usual, was lacking, and most of the examples I tried didn&#8217;t seem to actually output the trace to a file (at least not where I expected to find it).<\/p>\n<p>keywords: server 2008 client cert certificate permissions winhttpcfg<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I just spent a while tracking down a cert problem while migrating an app to IIS7 on Windows Server 2008. This app taps into a web service using a client cert. I finally tracked the problem down to a permissions issue with the private key on the client certificate. On Server 2003 and earlier these &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.mattjm.com\/blog\/2009\/12\/07\/client-certs-and-windows-server-2008\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Client Certs and Windows Server 2008&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[1,7],"tags":[],"_links":{"self":[{"href":"https:\/\/www.mattjm.com\/blog\/wp-json\/wp\/v2\/posts\/238"}],"collection":[{"href":"https:\/\/www.mattjm.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.mattjm.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.mattjm.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mattjm.com\/blog\/wp-json\/wp\/v2\/comments?post=238"}],"version-history":[{"count":1,"href":"https:\/\/www.mattjm.com\/blog\/wp-json\/wp\/v2\/posts\/238\/revisions"}],"predecessor-version":[{"id":402,"href":"https:\/\/www.mattjm.com\/blog\/wp-json\/wp\/v2\/posts\/238\/revisions\/402"}],"wp:attachment":[{"href":"https:\/\/www.mattjm.com\/blog\/wp-json\/wp\/v2\/media?parent=238"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.mattjm.com\/blog\/wp-json\/wp\/v2\/categories?post=238"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.mattjm.com\/blog\/wp-json\/wp\/v2\/tags?post=238"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}